Skip to main content
REALIZED.TEAM
Book Workshop

Compliance · Evidence Matrix

Governance is the product.

Every regulatory obligation maps to a runtime control with exportable evidence. No bolt-on audit tooling, no quarterly scramble — the platform produces the artifact at the moment of execution.

Regulatory Surface

Frameworks, controls, evidence.

Five frameworks gate enterprise AI deployment in 2026. Each one is mapped to specific platform controls and the evidence we can produce on demand.

Status

OWASP ASI 2026

Aligned · all 10 ASI controls mapped to platform features

Scope
Agentic application security baseline — 10 risk categories for autonomous systems.

  • Control

    ASI01–ASI10 mitigations native to the runtime

    Evidence we produce

    Per-risk product feature mapping (see below)

  • Control

    Continuous red-team coverage of ASI categories

    Evidence we produce

    Quarterly external pentest report on request

Status

EU AI Act — Art. 12, 14

Native · Stop Button + immutable logs ship by default

Scope
High-risk AI system obligations: logging, human oversight, transparency.

  • Control

    Art. 12 — automated event logging across the agent lifecycle

    Evidence we produce

    Cryptographically signed audit trail, exportable per workflow

  • Control

    Art. 14 — effective human oversight and shutdown

    Evidence we produce

    Per-workflow Stop Button + HITL surface with uncertainty scoring

  • Control

    Art. 13 — instructions for use and transparency

    Evidence we produce

    Per-workflow model card + tool inventory generated at deploy time

Status

ISO/IEC 42001

Built-in · evidence collected automatically per deployment

Scope
AI management system — governance, risk, lifecycle, supplier obligations.

  • Control

    AI risk register tied to each workflow

    Evidence we produce

    Risk-to-control mapping exported as part of the deployment manifest

  • Control

    Change management with versioned policies

    Evidence we produce

    Git-backed policy plane, every change reviewable and reversible

  • Control

    Third-party model and tool registry

    Evidence we produce

    Vendor inventory with provenance and version pinning

Status

SOC 2 Type II

Aligned · annual external audit, report under NDA

Scope
Trust services criteria — security, availability, confidentiality.

  • Control

    Access reviews and least-privilege enforcement

    Evidence we produce

    Quarterly access certification reports

  • Control

    Change management and segregation of duties

    Evidence we produce

    Production change log + reviewer attestations

  • Control

    Incident response runbooks and SLAs

    Evidence we produce

    Post-mortem repository, MTTR metrics on request

Status

FINMA Circular 08/2024

Built-in · controls map directly to circular sections 4–6

Scope
Swiss financial services — operational risk and outsourcing of AI services.

  • Control

    Model risk inventory and ongoing validation

    Evidence we produce

    Per-workflow validation report, refreshed on retrain

  • Control

    Outsourcing oversight and exit plan

    Evidence we produce

    Data residency controls (CH/EU) + documented exit procedures

  • Control

    Independent audit access to decisioning evidence

    Evidence we produce

    Read-only audit role with full execution trail visibility

Status

Swiss FADP — Art. 21

Native · contestation workflow ships with every decision surface

Scope
Automated individual decisions — transparency, contestation, human review.

  • Control

    Notification of automated decisions to data subjects

    Evidence we produce

    Templated notice generated per decision class

  • Control

    Right to human review of automated outcomes

    Evidence we produce

    Built-in review queue routed to designated reviewers

  • Control

    Logic, scope, and consequences disclosed on request

    Evidence we produce

    Per-decision rationale exportable in plain language

OWASP ASI 2026 — Full Mapping

Ten agentic risks. Ten runtime controls.

Each row maps an ASI risk category to its mitigation strategy and the product feature that enforces it. None of these are configurable away — they are the runtime.

Evidence Pack

Need the underlying artifacts?

SOC 2 Type II report, ISO 42001 statement of applicability, FINMA mapping, and signed audit-log samples are available under NDA. Workshop attendees receive the full pack at scoping.

Request the evidence pack